Does Reg F apply to your credit union?

The short answer is fact-specific. Reg F implements the FDCPA, whose federal debt-collector definition often excludes an original creditor collecting its own debt. That is not a universal exemption: debt ownership, acquisition history, participant role, actual conduct, and state law can change the analysis. Counsel should approve the classification for each operating model.

Using a third-party vendor does not automatically end an original-creditor analysis, and presenting the creditor’s name does not automatically preserve one. The important evidence is who selected the account, who determined the communication, who exercised collection discretion, what authority each participant had, and which law applies. Vendor oversight remains necessary regardless of the resulting classification.

A role-aware platform should therefore preserve the operating facts instead of assigning one legal label to every workflow. It should identify the sender and represented participant, bind communication policy to the account and jurisdiction, and fail closed until the required controls are approved.

The key distinction. Reg F §1006.2(e) defines “consumer.” It does not define a technology-provider category or decide FDCPA coverage. Sender identity is one operating fact, not a statutory shortcut. Record role, authority, conduct, account context, and jurisdiction, then apply the counsel-approved policy for that configuration.

Reg F §1006.14(b)(2): the telephone-frequency presumptions

For workflows involving a covered debt collector, §1006.14(b)(2) creates rebuttable presumptions of compliance and violation for telephone calls to a particular person about a particular debt. These are not a generic cap on every channel, and the rule includes exclusions:

Reg F §1006.14(b)(2) telephone-call framework

Fact patternRegulatory presumption
No more than 7 calls in 7 consecutive days to a particular person about a particular debtPresumed compliant with the frequency rule
More than 7 calls in that periodPresumed violation
A call within 7 consecutive days after a telephone conversation about that debtPresumed violation
Counting unitParticular person and particular debt, subject to exclusions

A few operational notes that frequently trip up compliance teams:

  • The framework is tied to a particular debt. A member may have multiple debts, so a participant should also impose an aggregate relationship guardrail instead of treating the regulatory presumption as an outreach target.
  • Count conservatively. The rule excludes specified calls, including calls that do not connect to the dialed number. The workflow should retain the disposition and the basis for any exclusion rather than silently dropping attempts.
  • The seven-day period is consecutive. It does not reset on a chosen weekday. A rolling ledger is safer than a weekly batch counter.
  • The presumption is telephone-specific. Email and text have separate third-party-disclosure, address or number, opt-out, and medium-choice controls under §1006.6 and §1006.14(h).

Electronic communication: opt-in, opt-out, and the consent chain

Reg F §1006.6(d) describes reasonable procedures designed to avoid prohibited third-party disclosures in email and text communications, while §1006.6(e) requires a clear and conspicuous, reasonable and simple opt-out method. The exact procedure depends on how the address or number was obtained:

Path 1: Address or number used with the collector

The rule provides procedures for an address or number the consumer used to communicate with the collector, or for which the collector received consent directly, provided the relevant opt-out, withdrawal, recency, and reassignment conditions are satisfied. Preserve the source and date instead of treating contact data as interchangeable.

Path 2: Contact data transferred by a creditor or prior collector

Creditor-supplied email procedures require more than merely possessing the address. Among other conditions, the creditor must have obtained and used it for the account and must send the rule’s transfer notice with a reasonable opt-out method and at least a 35-day response period before collector use. Text-message procedures have their own conditions. Model each provenance path explicitly.

Path 3: Opt-out rights under §1006.6(e)

Every electronic communication must include a clear, conspicuous, and reasonable opt-out mechanism. The CFPB has been specific: “reasonable” means a mechanism the consumer can use without undue burden: a reply of “STOP” to a text, or a one-click unsubscribe link in an email. Burying the opt-out at the bottom of a multi-screen scroll does not satisfy the rule.

Once a person requests that a collector not use a medium, §1006.14(h) generally prohibits further communication through that medium, subject to narrow exceptions. A platform should block the medium immediately, preserve the request, and allow only a qualifying confirmation or other counsel-approved exception.

Cease communication vs. channel opt-out: they are different. A qualifying written cease-communication notice under §1692c(c) is broader, subject to statutory exceptions. An electronic opt-out under Reg F §1006.6(e) and a medium request under §1006.14(h) govern the specified electronic address, number, or medium. Make sure the workflow records the request type, scope, sender, account, and permitted exceptions.

Cease-and-desist handling for credit unions

Even when a credit union is not itself a debt collector, the contractual obligations of your third-party collectors flow back to you through vendor management. If a member sends a written cease-and-desist request to your collector, the FDCPA §1692c(c) requires the collector to stop all communication except to confirm the cessation or notify the consumer of a specific action (like a lawsuit).

The operational risk for credit unions is twofold:

  • The cease-and-desist must reach the collector promptly. If a member sends the letter to your credit union (as the original creditor) and your CU does not route it to the collector within a day or two, you have created a gap where the collector continues contact in good faith but the member’s legal right has already been invoked.
  • The account must be flagged across all contact channels. A cease-and-desist stops telephone calls, letters, emails, and texts. A collector who stops calls but continues email is still in violation.

Credit unions should audit whether their loan-servicing system and their third-party collector systems share a cease-and-desist flag in real time. This is one of the most common exam findings in vendor-management reviews at the state level.

How a role-aware workflow platform helps

Software cannot decide legal status by naming itself. It can make the operating model legible and enforce the controls approved for each participant and account:

  1. Make every participant explicit. Record the creditor, owner, servicer, collector, firm, representative, communication sender, and decision-maker independently instead of collapsing them into one label.
  2. Bind policy to the real context. Select disclosures, quiet hours, frequency rules, representation blocks, channel permissions, and approval gates from the participant, state, account, and communication context.
  3. Preserve evidence and fail closed. Keep the contact-data provenance, authority, policy version, decision, and delivery result. If classification or required configuration is missing, hold the action for review.

The practical result is one shared record of the account and its actors, with different controls and views for each role. Counsel still determines legal coverage; the platform makes that determination enforceable and auditable.

Role-aware workflow controls

RequirementPlatform treatment
Reg F §1006.14(b)(2) telephone-frequency presumptionsEnforced when the approved participant/account policy requires them
Reg F electronic communication controlsSelected by role, contact-data provenance, channel, and policy
Cease-communication and representation routingShared account-level holds with scoped exceptions
Legal coverageCounsel determination required; never inferred from branding alone
Consumer-facing identityExplicit sender, represented participant, and account context
Audit evidenceVersioned policy, decision, authority, event, and delivery result

What ‘pilot’ looks like in practice

Most credit unions want to validate the workflow before authorizing a paid subscription. The pilot structure is explicit:

  • No-charge pilot. The credit union enrolls an approved account segment and tests configured workflows. The pilot does not auto-convert and creates no platform invoice.
  • Flat monthly subscription only after separate authorization. Standard service begins only after an owner accepts a versioned order form and pricing schedule. Charges never vary with amounts collected, settlements, or recovery outcomes.
  • Participant policy confirmed at onboarding. Before live communication, the platform records the data agreement, legal terms, participant roles, sender authority, jurisdictional policy, and compliance approval for the workflow.
  • Audit trail by default. Every offer, every communication, every payment, every member response produces an immutable log that your CU can pull for examiner review without asking the vendor for a data export.
  • Member contact policy is versioned. Approved cadence, channel, representation, cease-communication, and disclosure rules are encoded in software and bound to the participant/account context.

What examiners are looking for in 2026

NCUA and state regulators have been clear that Reg F compliance is a vendor management priority, not just a direct-collections priority. In 2025 and 2026, examination findings increasingly target the gap between what creditors believe their third-party collectors are doing and what the collectors are actually doing.

The three areas generating the most findings:

  • Cease-and-desist routing gaps. Cease-and-desist letters arriving at the credit union and not reaching the collector within 48 hours, leaving the collector contacting a member whose rights have already been invoked.
  • Electronic opt-out confirmation failures. Collectors not providing written confirmation of opt-out to the consumer within the required window, and not updating the account flag across all contact channels.
  • Insufficient vendor oversight documentation. Credit unions that cannot produce evidence of regular vendor audits, contract reviews, or complaint-tracking for their collection vendors.

The platform does not replace legal analysis or participant oversight. It turns the approved operating model into shared, testable controls.

See how Debt Digest works for credit unions

No-charge pilot with no automatic conversion. Standard service requires a separate subscription order form. No contingency or recovery-based pricing.

See the credit union overview