SOURCES

Every instrument this site cites, with its status and the date it was last verified.

About forty instruments, each with its status, who it reaches and who it does not, its primary source and the date last verified.

Register last checked 23 September 2026.

How to read a row.

The five statuses
StatusWhat it means
In forceBinds today: current and applicable to the population named, as rule or supervisory guidance.
Not yet in effectEnacted or issued; effective on a future date.
Withdrawn or supersededRemoved or replaced; kept for the record and cited only to say so.
VoluntaryBinds nobody by law; no regulator examines against it; a counterparty may adopt it by contract.
ContractualBinds by contract, not supervision: any signatory, any size, and nobody else.
Red dashed: not yet binding.

Verified: the day we last read the instrument at its primary source.

Two rules govern this register. Nothing is cited on this site that is not on this page, and every citation on this site carries who the instrument reaches and who it does not in the same block as the obligation. Where an instrument cannot be verified at its primary source, the sentence that relied on it is removed from the site rather than softened.

Information security.

Banks and examiners
InstrumentStatusReachesNotVerified
Interagency Guidelines Establishing Information Security Standards, 12 CFR Part 30 Appendix B, Part 364 Appendix B, Part 208 Appendix D-2, Part 225 Appendix FIn force.Every insured depository institution and its subsidiaries, any size.Credit unions or nonbank lenders.23 September 2026
Interagency Guidance on Third-Party Relationships: Risk Management, 88 FR 37920, OCC Bulletin 2023-17, SR 23-4, FIL-29-2023In force as guidance since June 2023.Every bank the OCC, Federal Reserve and FDIC supervise, any asset size.Credit unions; NCUA is not a party.23 September 2026
Computer-Security Incident Notification Rule, 12 CFR Part 53, Part 225 Subpart N, Part 304 Subpart CIn force since 1 May 2022.Banking organizations of any size, and bank service providers.Credit unions and nonbank lenders.23 September 2026
FFIEC IT Examination Handbook, with the Development, Acquisition and Maintenance booklet of August 2024In force as guidance.Banks, thrifts, credit unions, technology service providers.Anyone as law: no independent legal obligation.23 September 2026
FFIEC Cybersecurity Assessment Tool, Sunset StatementWithdrawn or superseded, 31 August 2025.Nobody. It was voluntary throughout.Any obligation; the Statement endorses no replacement.23 September 2026
Credit unions
InstrumentStatusReachesNotVerified
NCUA 12 CFR Part 748, Appendix A and Appendix B; Letter 07-CU-13 and Supervisory Letter 07-01In force; the letters as guidance.Every federally insured credit union, any asset size. Vendors: Appendix A, III.D, and the letters.Banks.23 September 2026
NCUA cyber incident notification, 12 CFR 748.1(c)In force since 1 September 2023.Every federally insured credit union, any size.Banks. Excluded: good faith activity at the system owner's or operator's request, including authorized penetration testing.23 September 2026
NCUA Information Security Examination procedures: SCUEP, CORE and CORE+In force since 2023.Federally insured credit unions.Banks. The voluntary ACET self assessment remains.23 September 2026
Lenders and public companies
InstrumentStatusReachesNotVerified
Gramm-Leach-Bliley Act, Title V, Subtitle A, 15 U.S.C. 6801 to 6809In force.Financial institutions of every kind, bank and nonbank.Its own size threshold; the implementing rules set any.23 September 2026
FTC Safeguards Rule, 16 CFR Part 314, with 314.6 and 314.4(j)In force; 314.4(j) since 13 May 2024.Nonbank financial institutions under FTC jurisdiction, mortgage companies included.Banks, savings associations, federally insured credit unions. Exempt: below 5,000 consumers, no written risk assessment (one is still owed), testing cadence, written incident response plan or annual board report. The rest, service provider oversight and the 30 day FTC notice at 500 or more consumers included, applies at every size.23 September 2026
NYDFS Cybersecurity Regulation, 23 NYCRR Part 500, with 500.19(a) and 500.17In force; amended requirements effective 1 November 2025.Holders of a DFS license, registration, charter or authorization.A firm that merely lends to a New York resident. Exempt: fewer than 20 employees and contractors across the entity and its affiliates, or under $7.5 million in gross annual revenue in each of the last three fiscal years counting all of its own operations plus its affiliates' New York operations, or under $15 million in year end total assets calculated under GAAP and including the assets of all affiliates. It never removes the 72 hour or 24 hour notices in 500.17.23 September 2026
SEC Form 8-K Item 1.05 and Regulation S-K Item 106In force. An industry petition to rescind Item 1.05 is pending.Public companies reporting under the Exchange Act.Privately held firms.23 September 2026
Breach law and others
InstrumentStatusReachesNotVerified
Louisiana Database Security Breach Notification Law, La. R.S. 51:3071 to 51:3077In force as amended.Anyone doing business in Louisiana or holding its residents' covered information.Subject to a documented risk of harm determination and an encryption safe harbor. Exempt: financial institutions complying with the banking regulators' GLBA guidance.23 September 2026
State breach notification statutes: every state, the District of Columbia, the territoriesIn force, amended often.Anyone holding a state's residents' data, on that state's terms.A general rule: this site states none, only a named state's numbers.9 September 2026
CISA Known Exploited Vulnerabilities CatalogIn force; updated continuously.Federal civilian executive branch agencies, bound by remediation timelines set under Binding Operational Directive 26-04, which superseded Binding Operational Directive 22-01 in June 2026.You: this site uses it to rank, not as your deadline.23 September 2026
SOC 2, AICPA Trust Services CriteriaVoluntary; 2017 criteria with 2022 points of focus current.Required by nobody; counterparties demand it by contract.A certification or regulation: it reports on a provider's own selected controls.9 September 2026

Insurance.

Data security
InstrumentStatusReachesNotVerified
NAIC Insurance Data Security Model Law, Model #668, with the Section 9 exemptionsIn force where enacted, in a substantial number of states, uncounted here.Licensees in a state that enacted it; the enacted text governs.Other states' licensees. Exempt from the written program only: fewer than 10 employees, including independent contractors; a HIPAA compliant program; an employee or agent under another licensee's program.23 September 2026
Louisiana Insurance Data Security Law, La. R.S. 22:2501 and following, Act 283 of 2020In force since 1 August 2020; program since 1 August 2021; service providers since 1 August 2022.Licensees of the Louisiana Department of Insurance.Anyone else. Exempt from the program requirement in R.S. 22:2504, under R.S. 22:2509(A): fewer than 25 employees, under $5 million in gross annual revenue or $10 million in year end assets, a HIPAA compliant program, or a depository institution affiliate under the Interagency Guidelines, among others. Investigation and notice remain.23 September 2026
AI and conduct
InstrumentStatusReachesNotVerified
NAIC AI Model Bulletin and implementation mapIn force where adopted: 24 states and the District of Columbia on the map dated 31 August 2026; four states act through their own instruments. Not Louisiana.Insurers in an adopting state using AI systems in decisions affecting consumers.Insurers elsewhere. Producers or administrators: a state by state question.23 September 2026
NAIC AI Systems Evaluation Tool pilot, Big Data and Artificial Intelligence Working GroupVoluntary. From 2 March 2026 through September, twelve departments including Louisiana; updated tool expected November 2026.Those departments' domestic insurers, under existing examination authority.Any duty: no insurer owes anything under it.23 September 2026
Market conduct examination and the NAIC Market Regulation HandbookIn force.Insurers and, depending on the state, producers and other licensees.No specific examination standard is quoted on this site.23 September 2026
Colorado SB 21-169 and Regulation 10-1-1, 3 CCR 702-10In force; amended Regulation 10-1-1 effective 15 October 2025.Colorado life, private passenger automobile and health benefit plan insurers using external consumer data and information sources, or models built on them.A firm outside Colorado's insurance market.23 September 2026

Mortgage.

Fannie Mae, Freddie Mac
InstrumentStatusReachesNotVerified
Fannie Mae Information Security and Business Resiliency Supplement, Selling and Servicing GuidesContractual; all compliance dates passed.Single-Family sellers and servicers, Multifamily lenders, technology service providers, document custodians; any size.Anyone outside a Fannie Mae relationship.23 September 2026
Fannie Mae Lender Letter LL-2026-04 of 8 April 2026; Freddie Mac Guide Section 1302.8, Bulletin 2025-16 of 3 December 2025Contractual. Effective 6 August 2026 and 3 March 2026.Seller/Servicers using AI or machine learning in origination or servicing: a written governance framework, elements on Mortgage.Anyone outside either contract.23 September 2026
Freddie Mac Single-Family Seller/Servicer Guide, Chapter 1302, Sections 1302.2 and 1302.3, as revised by Bulletin 2025-13Contractual. Information security requirements in force since 3 July 2023; Bulletin 2025-13 revisions effective 1 January 2026.Freddie Mac Sellers and Servicers and any organization that stores, processes or transmits Freddie Mac protected information or connects to its systems, with no size exemption: notice within 48 hours of discovery including incidents at third parties, penetration testing at least annually by a qualified and independent third party, an annual independent security assessment and an annual incident response test.Nobody without a Freddie Mac contract.23 September 2026
Ginnie Mae, FHA, licensing
InstrumentStatusReachesNotVerified
Ginnie Mae APM 24-02, amending the MBS Guide, issued 4 March 2024In force. Checked against the issuer's index and two published summaries.Approved Issuers of any size, subservicers included.Anyone else under it; a custodian confirms its own position.23 September 2026
HUD Mortgagee Letter 2024-23, 2 December 2024In force; supersedes Mortgagee Letter 2024-10.FHA approved mortgagees, bank or nonbank, any size.Nobody without FHA approval.23 September 2026
SAFE Act, Regulation H, 12 CFR Part 1008, and the NMLS, run by the Conference of State Bank SupervisorsIn force.Individuals who habitually take residential mortgage applications or negotiate terms for pay, and their employers.Originators at depository institutions, registered federally. No cybersecurity duty.23 September 2026
CFPB supervision and examination authority, Consumer Financial Protection ActIn force; examination posture not stated here.Depository institutions and credit unions above the statutory asset threshold; nonbank covered persons, mortgage companies included.Institutions outside those categories.9 September 2026

Credit decisions.

Notices
InstrumentStatusReachesNotVerified
ECOA and Regulation B adverse action notice, 12 CFR 1002.9In force; Section 1002.9 was not changed by the 2026 final rule.Every creditor: specific principal reasons, however the decision was reached, model or no model.No general size exemption for consumer credit; business credit under 1002.9(a)(3).23 September 2026
Regulation B final rule, Federal Register document 2026-07804, published 22 April 2026In force since 21 July 2026.Creditors: effects test language removed from 1002.6(a), discouragement narrowed, conditions on for profit special purpose credit programs.1002.9, which it left untouched. It reaches ECOA only.23 September 2026
FCRA section 615(a), 15 U.S.C. 1681m(a), with the credit score disclosure at 1681m(a)(2)In force.Anyone taking adverse action based at all on a consumer report; any score used is disclosed.Met by the Regulation B reasons alone; one form may carry both.23 September 2026
Risk based pricing rule, Regulation V, 12 CFR Part 1022 Subpart HIn force.Users of a consumer report who, based on it, grant consumer credit on materially less favorable terms.Business purpose credit, or a 1022.74 exception, including where an adverse action notice was given.23 September 2026
Housing and valuation
InstrumentStatusReachesNotVerified
Fair Housing Act, 42 U.S.C. 3605, administered by HUDIn force.Anyone whose business includes residential real estate related transactions, including making or purchasing loans secured by residential real estate, independently of ECOA.A size test: scope follows the business. Only the section's text is stated here.9 September 2026
AVM quality control standards, six agencies, published 7 August 2024In force since 1 October 2025.Originators and secondary market issuers valuing a consumer's principal dwelling with an AVM.An appraiser's use in an appraisal, or review of a completed valuation.23 September 2026

AI governance.

Guidance and frameworks
InstrumentStatusReachesNotVerified
SR 26-2 and OCC Bulletin 2026-13 on model risk, with the FDIC issuance, 17 April 2026In force as guidance.Banks the three agencies supervise. The agencies state it is most relevant above $30 billion in total assets and place generative and agentic AI outside it; smaller banks' models remain subject to governance appropriate to size and risk profile.Credit unions, insurers, nonbank lenders.23 September 2026
NYDFS industry letter on AI cybersecurity risks, 16 October 2024In force; it imposes no new requirement.Covered Entities under 23 NYCRR Part 500, on its reach and limited exemption.Anyone outside DFS authorization.23 September 2026
NIST AI RMF 1.0, AI 100-1, released 26 January 2023; Generative AI Profile, AI 600-1, released 26 July 2024Voluntary. NIST states version 1.0 is being revised under the 2025 AI Action Plan; none published at last review.Anyone who chooses them; a counterparty may adopt them by contract.Anyone by law. No regulator examines against them.23 September 2026
ISO/IEC 42001:2023, AI management system, first edition, December 2023Voluntary; accredited bodies certify.Organizations that adopt it.Anyone by law; a certificate speaks to the management system only.23 September 2026
Laws and orders
InstrumentStatusReachesNotVerified
EU AI Act, Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744In force in phases: prohibitions and AI literacy since 2 February 2025, general purpose models since 2 August 2025, transparency from 2 August 2026. Annex III high risk, credit scoring included, deferred to 2 December 2027 by the amendment of 8 July 2026, published 24 July 2026.Providers and deployers of AI placed on the EU market or whose output is used there.A United States institution without EU nexus, which this site does not decide.23 September 2026
Executive Order 14365, 11 December 2025, and the White House framework of 20 March 2026In force as to federal agencies; the framework is nonbinding; no preemption statute at last review.Federal agencies only. Its effect runs through litigation, including the Department of Justice intervention in Colorado.Private entities. It displaces no state statute by itself.23 September 2026
Colorado SB 26-189, signed 14 May 2026; stipulated order of 27 April 2026, xAI LLC v. Weiser, D. Colo. 1:26-cv-01515Not yet in effect: scheduled for 1 January 2027, with enforcement of both statutes stayed until fourteen days after the court rules on xAI's motion for a preliminary injunction.Developers and deployers of covered automated decision making technology with a Colorado nexus.Insurers complying with Colorado insurance law on algorithms, deemed compliant.23 September 2026

This firm builds the program and the evidence to the shape the instrument requires. Counsel confirms the legal reading for your state.

Withdrawals and corrections.

No page here relies on a withdrawn instrument.

Withdrawn and superseded instruments
InstrumentWhat happenedDate
CFPB Circulars 2022-03 and 2023-03, on adverse action notices where a complex algorithm shaped the decisionWithdrawn in Federal Register document 2025-08286. The duty they described sits in 12 CFR 1002.9 and its official commentary, which were not withdrawn and which the 2026 final rule did not amend.12 May 2025
Federal Reserve SR 11-7 and SR 21-8, OCC Bulletins 2011-12, 2021-19 and 1997-24, the OCC Model Risk Management booklet, and FDIC FIL-22-2017 and FIL-27-2021Superseded or rescinded by SR 26-2 and OCC Bulletin 2026-13.17 April 2026
HUD Mortgagee Letter 2024-10, a twelve hour clock from detectionSuperseded by Mortgagee Letter 2024-23: 36 hours from determination. The clock map and Mortgage carry it.2 December 2024
OCC Bulletins 2013-29, 2017-21 and 2020-10, on third party relationshipsOCC Bulletin 2017-21 rescinded by OCC Bulletin 2020-10 in March 2020; 2013-29 and 2020-10 by OCC Bulletin 2023-17.June 2023
FFIEC Cybersecurity Assessment ToolRemoved with no designated successor; this site names none.31 August 2025
Colorado SB 24-205, the Colorado Artificial Intelligence Act of 2024Stayed by a federal court in April 2026, then replaced by SB 26-189, under the same stay.14 May 2026
Binding Operational Directive 22-01Revoked; superseded by BOD 26-04.June 2026

Corrections to this site's own text

A sentence corrected after first publication is listed here with its date and page, and stays listed. None yet.

Maintenance.

Each row's register entry records its source, checker, check date and next due date. Rechecks: every row on any material site update; rows marked changing quarterly, stable rows annually; the NAIC map on each reissue; the SEC row before each republication while the Item 1.05 petition is pending; the Executive Order row when Congress acts on federal AI preemption; the Colorado row when xAI files or the court rules.

A changed instrument changes every page citing it that day, with a line in the corrections list.

Take the notification clock map

Bring the instrument that reached your desk.