SOURCES
Every instrument this site cites, with its status and the date it was last verified.
About forty instruments, each with its status, who it reaches and who it does not, its primary source and the date last verified.
How to read a row.
| Status | What it means |
|---|---|
| In force | Binds today: current and applicable to the population named, as rule or supervisory guidance. |
| Not yet in effect | Enacted or issued; effective on a future date. |
| Withdrawn or superseded | Removed or replaced; kept for the record and cited only to say so. |
| Voluntary | Binds nobody by law; no regulator examines against it; a counterparty may adopt it by contract. |
| Contractual | Binds by contract, not supervision: any signatory, any size, and nobody else. |
Verified: the day we last read the instrument at its primary source.
Two rules govern this register. Nothing is cited on this site that is not on this page, and every citation on this site carries who the instrument reaches and who it does not in the same block as the obligation. Where an instrument cannot be verified at its primary source, the sentence that relied on it is removed from the site rather than softened.
Information security.
| Instrument | Status | Reaches | Not | Verified |
|---|---|---|---|---|
| Interagency Guidelines Establishing Information Security Standards, 12 CFR Part 30 Appendix B, Part 364 Appendix B, Part 208 Appendix D-2, Part 225 Appendix F | In force. | Every insured depository institution and its subsidiaries, any size. | Credit unions or nonbank lenders. | 23 September 2026 |
| Interagency Guidance on Third-Party Relationships: Risk Management, 88 FR 37920, OCC Bulletin 2023-17, SR 23-4, FIL-29-2023 | In force as guidance since June 2023. | Every bank the OCC, Federal Reserve and FDIC supervise, any asset size. | Credit unions; NCUA is not a party. | 23 September 2026 |
| Computer-Security Incident Notification Rule, 12 CFR Part 53, Part 225 Subpart N, Part 304 Subpart C | In force since 1 May 2022. | Banking organizations of any size, and bank service providers. | Credit unions and nonbank lenders. | 23 September 2026 |
| FFIEC IT Examination Handbook, with the Development, Acquisition and Maintenance booklet of August 2024 | In force as guidance. | Banks, thrifts, credit unions, technology service providers. | Anyone as law: no independent legal obligation. | 23 September 2026 |
| FFIEC Cybersecurity Assessment Tool, Sunset Statement | Withdrawn or superseded, 31 August 2025. | Nobody. It was voluntary throughout. | Any obligation; the Statement endorses no replacement. | 23 September 2026 |
| Instrument | Status | Reaches | Not | Verified |
|---|---|---|---|---|
| NCUA 12 CFR Part 748, Appendix A and Appendix B; Letter 07-CU-13 and Supervisory Letter 07-01 | In force; the letters as guidance. | Every federally insured credit union, any asset size. Vendors: Appendix A, III.D, and the letters. | Banks. | 23 September 2026 |
| NCUA cyber incident notification, 12 CFR 748.1(c) | In force since 1 September 2023. | Every federally insured credit union, any size. | Banks. Excluded: good faith activity at the system owner's or operator's request, including authorized penetration testing. | 23 September 2026 |
| NCUA Information Security Examination procedures: SCUEP, CORE and CORE+ | In force since 2023. | Federally insured credit unions. | Banks. The voluntary ACET self assessment remains. | 23 September 2026 |
| Instrument | Status | Reaches | Not | Verified |
|---|---|---|---|---|
| Gramm-Leach-Bliley Act, Title V, Subtitle A, 15 U.S.C. 6801 to 6809 | In force. | Financial institutions of every kind, bank and nonbank. | Its own size threshold; the implementing rules set any. | 23 September 2026 |
| FTC Safeguards Rule, 16 CFR Part 314, with 314.6 and 314.4(j) | In force; 314.4(j) since 13 May 2024. | Nonbank financial institutions under FTC jurisdiction, mortgage companies included. | Banks, savings associations, federally insured credit unions. Exempt: below 5,000 consumers, no written risk assessment (one is still owed), testing cadence, written incident response plan or annual board report. The rest, service provider oversight and the 30 day FTC notice at 500 or more consumers included, applies at every size. | 23 September 2026 |
| NYDFS Cybersecurity Regulation, 23 NYCRR Part 500, with 500.19(a) and 500.17 | In force; amended requirements effective 1 November 2025. | Holders of a DFS license, registration, charter or authorization. | A firm that merely lends to a New York resident. Exempt: fewer than 20 employees and contractors across the entity and its affiliates, or under $7.5 million in gross annual revenue in each of the last three fiscal years counting all of its own operations plus its affiliates' New York operations, or under $15 million in year end total assets calculated under GAAP and including the assets of all affiliates. It never removes the 72 hour or 24 hour notices in 500.17. | 23 September 2026 |
| SEC Form 8-K Item 1.05 and Regulation S-K Item 106 | In force. An industry petition to rescind Item 1.05 is pending. | Public companies reporting under the Exchange Act. | Privately held firms. | 23 September 2026 |
| Instrument | Status | Reaches | Not | Verified |
|---|---|---|---|---|
| Louisiana Database Security Breach Notification Law, La. R.S. 51:3071 to 51:3077 | In force as amended. | Anyone doing business in Louisiana or holding its residents' covered information. | Subject to a documented risk of harm determination and an encryption safe harbor. Exempt: financial institutions complying with the banking regulators' GLBA guidance. | 23 September 2026 |
| State breach notification statutes: every state, the District of Columbia, the territories | In force, amended often. | Anyone holding a state's residents' data, on that state's terms. | A general rule: this site states none, only a named state's numbers. | 9 September 2026 |
| CISA Known Exploited Vulnerabilities Catalog | In force; updated continuously. | Federal civilian executive branch agencies, bound by remediation timelines set under Binding Operational Directive 26-04, which superseded Binding Operational Directive 22-01 in June 2026. | You: this site uses it to rank, not as your deadline. | 23 September 2026 |
| SOC 2, AICPA Trust Services Criteria | Voluntary; 2017 criteria with 2022 points of focus current. | Required by nobody; counterparties demand it by contract. | A certification or regulation: it reports on a provider's own selected controls. | 9 September 2026 |
Insurance.
| Instrument | Status | Reaches | Not | Verified |
|---|---|---|---|---|
| NAIC Insurance Data Security Model Law, Model #668, with the Section 9 exemptions | In force where enacted, in a substantial number of states, uncounted here. | Licensees in a state that enacted it; the enacted text governs. | Other states' licensees. Exempt from the written program only: fewer than 10 employees, including independent contractors; a HIPAA compliant program; an employee or agent under another licensee's program. | 23 September 2026 |
| Louisiana Insurance Data Security Law, La. R.S. 22:2501 and following, Act 283 of 2020 | In force since 1 August 2020; program since 1 August 2021; service providers since 1 August 2022. | Licensees of the Louisiana Department of Insurance. | Anyone else. Exempt from the program requirement in R.S. 22:2504, under R.S. 22:2509(A): fewer than 25 employees, under $5 million in gross annual revenue or $10 million in year end assets, a HIPAA compliant program, or a depository institution affiliate under the Interagency Guidelines, among others. Investigation and notice remain. | 23 September 2026 |
| Instrument | Status | Reaches | Not | Verified |
|---|---|---|---|---|
| NAIC AI Model Bulletin and implementation map | In force where adopted: 24 states and the District of Columbia on the map dated 31 August 2026; four states act through their own instruments. Not Louisiana. | Insurers in an adopting state using AI systems in decisions affecting consumers. | Insurers elsewhere. Producers or administrators: a state by state question. | 23 September 2026 |
| NAIC AI Systems Evaluation Tool pilot, Big Data and Artificial Intelligence Working Group | Voluntary. From 2 March 2026 through September, twelve departments including Louisiana; updated tool expected November 2026. | Those departments' domestic insurers, under existing examination authority. | Any duty: no insurer owes anything under it. | 23 September 2026 |
| Market conduct examination and the NAIC Market Regulation Handbook | In force. | Insurers and, depending on the state, producers and other licensees. | No specific examination standard is quoted on this site. | 23 September 2026 |
| Colorado SB 21-169 and Regulation 10-1-1, 3 CCR 702-10 | In force; amended Regulation 10-1-1 effective 15 October 2025. | Colorado life, private passenger automobile and health benefit plan insurers using external consumer data and information sources, or models built on them. | A firm outside Colorado's insurance market. | 23 September 2026 |
Mortgage.
| Instrument | Status | Reaches | Not | Verified |
|---|---|---|---|---|
| Fannie Mae Information Security and Business Resiliency Supplement, Selling and Servicing Guides | Contractual; all compliance dates passed. | Single-Family sellers and servicers, Multifamily lenders, technology service providers, document custodians; any size. | Anyone outside a Fannie Mae relationship. | 23 September 2026 |
| Fannie Mae Lender Letter LL-2026-04 of 8 April 2026; Freddie Mac Guide Section 1302.8, Bulletin 2025-16 of 3 December 2025 | Contractual. Effective 6 August 2026 and 3 March 2026. | Seller/Servicers using AI or machine learning in origination or servicing: a written governance framework, elements on Mortgage. | Anyone outside either contract. | 23 September 2026 |
| Freddie Mac Single-Family Seller/Servicer Guide, Chapter 1302, Sections 1302.2 and 1302.3, as revised by Bulletin 2025-13 | Contractual. Information security requirements in force since 3 July 2023; Bulletin 2025-13 revisions effective 1 January 2026. | Freddie Mac Sellers and Servicers and any organization that stores, processes or transmits Freddie Mac protected information or connects to its systems, with no size exemption: notice within 48 hours of discovery including incidents at third parties, penetration testing at least annually by a qualified and independent third party, an annual independent security assessment and an annual incident response test. | Nobody without a Freddie Mac contract. | 23 September 2026 |
| Instrument | Status | Reaches | Not | Verified |
|---|---|---|---|---|
| Ginnie Mae APM 24-02, amending the MBS Guide, issued 4 March 2024 | In force. Checked against the issuer's index and two published summaries. | Approved Issuers of any size, subservicers included. | Anyone else under it; a custodian confirms its own position. | 23 September 2026 |
| HUD Mortgagee Letter 2024-23, 2 December 2024 | In force; supersedes Mortgagee Letter 2024-10. | FHA approved mortgagees, bank or nonbank, any size. | Nobody without FHA approval. | 23 September 2026 |
| SAFE Act, Regulation H, 12 CFR Part 1008, and the NMLS, run by the Conference of State Bank Supervisors | In force. | Individuals who habitually take residential mortgage applications or negotiate terms for pay, and their employers. | Originators at depository institutions, registered federally. No cybersecurity duty. | 23 September 2026 |
| CFPB supervision and examination authority, Consumer Financial Protection Act | In force; examination posture not stated here. | Depository institutions and credit unions above the statutory asset threshold; nonbank covered persons, mortgage companies included. | Institutions outside those categories. | 9 September 2026 |
Credit decisions.
| Instrument | Status | Reaches | Not | Verified |
|---|---|---|---|---|
| ECOA and Regulation B adverse action notice, 12 CFR 1002.9 | In force; Section 1002.9 was not changed by the 2026 final rule. | Every creditor: specific principal reasons, however the decision was reached, model or no model. | No general size exemption for consumer credit; business credit under 1002.9(a)(3). | 23 September 2026 |
| Regulation B final rule, Federal Register document 2026-07804, published 22 April 2026 | In force since 21 July 2026. | Creditors: effects test language removed from 1002.6(a), discouragement narrowed, conditions on for profit special purpose credit programs. | 1002.9, which it left untouched. It reaches ECOA only. | 23 September 2026 |
| FCRA section 615(a), 15 U.S.C. 1681m(a), with the credit score disclosure at 1681m(a)(2) | In force. | Anyone taking adverse action based at all on a consumer report; any score used is disclosed. | Met by the Regulation B reasons alone; one form may carry both. | 23 September 2026 |
| Risk based pricing rule, Regulation V, 12 CFR Part 1022 Subpart H | In force. | Users of a consumer report who, based on it, grant consumer credit on materially less favorable terms. | Business purpose credit, or a 1022.74 exception, including where an adverse action notice was given. | 23 September 2026 |
| Instrument | Status | Reaches | Not | Verified |
|---|---|---|---|---|
| Fair Housing Act, 42 U.S.C. 3605, administered by HUD | In force. | Anyone whose business includes residential real estate related transactions, including making or purchasing loans secured by residential real estate, independently of ECOA. | A size test: scope follows the business. Only the section's text is stated here. | 9 September 2026 |
| AVM quality control standards, six agencies, published 7 August 2024 | In force since 1 October 2025. | Originators and secondary market issuers valuing a consumer's principal dwelling with an AVM. | An appraiser's use in an appraisal, or review of a completed valuation. | 23 September 2026 |
AI governance.
| Instrument | Status | Reaches | Not | Verified |
|---|---|---|---|---|
| SR 26-2 and OCC Bulletin 2026-13 on model risk, with the FDIC issuance, 17 April 2026 | In force as guidance. | Banks the three agencies supervise. The agencies state it is most relevant above $30 billion in total assets and place generative and agentic AI outside it; smaller banks' models remain subject to governance appropriate to size and risk profile. | Credit unions, insurers, nonbank lenders. | 23 September 2026 |
| NYDFS industry letter on AI cybersecurity risks, 16 October 2024 | In force; it imposes no new requirement. | Covered Entities under 23 NYCRR Part 500, on its reach and limited exemption. | Anyone outside DFS authorization. | 23 September 2026 |
| NIST AI RMF 1.0, AI 100-1, released 26 January 2023; Generative AI Profile, AI 600-1, released 26 July 2024 | Voluntary. NIST states version 1.0 is being revised under the 2025 AI Action Plan; none published at last review. | Anyone who chooses them; a counterparty may adopt them by contract. | Anyone by law. No regulator examines against them. | 23 September 2026 |
| ISO/IEC 42001:2023, AI management system, first edition, December 2023 | Voluntary; accredited bodies certify. | Organizations that adopt it. | Anyone by law; a certificate speaks to the management system only. | 23 September 2026 |
| Instrument | Status | Reaches | Not | Verified |
|---|---|---|---|---|
| EU AI Act, Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 | In force in phases: prohibitions and AI literacy since 2 February 2025, general purpose models since 2 August 2025, transparency from 2 August 2026. Annex III high risk, credit scoring included, deferred to 2 December 2027 by the amendment of 8 July 2026, published 24 July 2026. | Providers and deployers of AI placed on the EU market or whose output is used there. | A United States institution without EU nexus, which this site does not decide. | 23 September 2026 |
| Executive Order 14365, 11 December 2025, and the White House framework of 20 March 2026 | In force as to federal agencies; the framework is nonbinding; no preemption statute at last review. | Federal agencies only. Its effect runs through litigation, including the Department of Justice intervention in Colorado. | Private entities. It displaces no state statute by itself. | 23 September 2026 |
| Colorado SB 26-189, signed 14 May 2026; stipulated order of 27 April 2026, xAI LLC v. Weiser, D. Colo. 1:26-cv-01515 | Not yet in effect: scheduled for 1 January 2027, with enforcement of both statutes stayed until fourteen days after the court rules on xAI's motion for a preliminary injunction. | Developers and deployers of covered automated decision making technology with a Colorado nexus. | Insurers complying with Colorado insurance law on algorithms, deemed compliant. | 23 September 2026 |
This firm builds the program and the evidence to the shape the instrument requires. Counsel confirms the legal reading for your state.
Withdrawals and corrections.
No page here relies on a withdrawn instrument.
| Instrument | What happened | Date |
|---|---|---|
| CFPB Circulars 2022-03 and 2023-03, on adverse action notices where a complex algorithm shaped the decision | Withdrawn in Federal Register document 2025-08286. The duty they described sits in 12 CFR 1002.9 and its official commentary, which were not withdrawn and which the 2026 final rule did not amend. | 12 May 2025 |
| Federal Reserve SR 11-7 and SR 21-8, OCC Bulletins 2011-12, 2021-19 and 1997-24, the OCC Model Risk Management booklet, and FDIC FIL-22-2017 and FIL-27-2021 | Superseded or rescinded by SR 26-2 and OCC Bulletin 2026-13. | 17 April 2026 |
| HUD Mortgagee Letter 2024-10, a twelve hour clock from detection | Superseded by Mortgagee Letter 2024-23: 36 hours from determination. The clock map and Mortgage carry it. | 2 December 2024 |
| OCC Bulletins 2013-29, 2017-21 and 2020-10, on third party relationships | OCC Bulletin 2017-21 rescinded by OCC Bulletin 2020-10 in March 2020; 2013-29 and 2020-10 by OCC Bulletin 2023-17. | June 2023 |
| FFIEC Cybersecurity Assessment Tool | Removed with no designated successor; this site names none. | 31 August 2025 |
| Colorado SB 24-205, the Colorado Artificial Intelligence Act of 2024 | Stayed by a federal court in April 2026, then replaced by SB 26-189, under the same stay. | 14 May 2026 |
| Binding Operational Directive 22-01 | Revoked; superseded by BOD 26-04. | June 2026 |
Corrections to this site's own text
A sentence corrected after first publication is listed here with its date and page, and stays listed. None yet.
Maintenance.
Each row's register entry records its source, checker, check date and next due date. Rechecks: every row on any material site update; rows marked changing quarterly, stable rows annually; the NAIC map on each reissue; the SEC row before each republication while the Item 1.05 petition is pending; the Executive Order row when Congress acts on federal AI preemption; the Colorado row when xAI files or the court rules.
A changed instrument changes every page citing it that day, with a line in the corrections list.