Does Reg F apply to your credit union?
The short answer is fact-specific. Reg F implements the FDCPA, whose federal debt-collector definition often excludes an original creditor collecting its own debt. That is not a universal exemption: debt ownership, acquisition history, participant role, actual conduct, and state law can change the analysis. Counsel should approve the classification for each operating model.
Using a third-party vendor does not automatically end an original-creditor analysis, and presenting the creditor’s name does not automatically preserve one. The important evidence is who selected the account, who determined the communication, who exercised collection discretion, what authority each participant had, and which law applies. Vendor oversight remains necessary regardless of the resulting classification.
A role-aware platform should therefore preserve the operating facts instead of assigning one legal label to every workflow. It should identify the sender and represented participant, bind communication policy to the account and jurisdiction, and fail closed until the required controls are approved.
Reg F §1006.14(b)(2): the telephone-frequency presumptions
For workflows involving a covered debt collector, §1006.14(b)(2) creates rebuttable presumptions of compliance and violation for telephone calls to a particular person about a particular debt. These are not a generic cap on every channel, and the rule includes exclusions:
Reg F §1006.14(b)(2) telephone-call framework
A few operational notes that frequently trip up compliance teams:
- The framework is tied to a particular debt. A member may have multiple debts, so a participant should also impose an aggregate relationship guardrail instead of treating the regulatory presumption as an outreach target.
- Count conservatively. The rule excludes specified calls, including calls that do not connect to the dialed number. The workflow should retain the disposition and the basis for any exclusion rather than silently dropping attempts.
- The seven-day period is consecutive. It does not reset on a chosen weekday. A rolling ledger is safer than a weekly batch counter.
- The presumption is telephone-specific. Email and text have separate third-party-disclosure, address or number, opt-out, and medium-choice controls under §1006.6 and §1006.14(h).
Electronic communication: opt-in, opt-out, and the consent chain
Reg F §1006.6(d) describes reasonable procedures designed to avoid prohibited third-party disclosures in email and text communications, while §1006.6(e) requires a clear and conspicuous, reasonable and simple opt-out method. The exact procedure depends on how the address or number was obtained:
Path 1: Address or number used with the collector
The rule provides procedures for an address or number the consumer used to communicate with the collector, or for which the collector received consent directly, provided the relevant opt-out, withdrawal, recency, and reassignment conditions are satisfied. Preserve the source and date instead of treating contact data as interchangeable.
Path 2: Contact data transferred by a creditor or prior collector
Creditor-supplied email procedures require more than merely possessing the address. Among other conditions, the creditor must have obtained and used it for the account and must send the rule’s transfer notice with a reasonable opt-out method and at least a 35-day response period before collector use. Text-message procedures have their own conditions. Model each provenance path explicitly.
Path 3: Opt-out rights under §1006.6(e)
Every electronic communication must include a clear, conspicuous, and reasonable opt-out mechanism. The CFPB has been specific: “reasonable” means a mechanism the consumer can use without undue burden: a reply of “STOP” to a text, or a one-click unsubscribe link in an email. Burying the opt-out at the bottom of a multi-screen scroll does not satisfy the rule.
Once a person requests that a collector not use a medium, §1006.14(h) generally prohibits further communication through that medium, subject to narrow exceptions. A platform should block the medium immediately, preserve the request, and allow only a qualifying confirmation or other counsel-approved exception.
Cease-and-desist handling for credit unions
Even when a credit union is not itself a debt collector, the contractual obligations of your third-party collectors flow back to you through vendor management. If a member sends a written cease-and-desist request to your collector, the FDCPA §1692c(c) requires the collector to stop all communication except to confirm the cessation or notify the consumer of a specific action (like a lawsuit).
The operational risk for credit unions is twofold:
- The cease-and-desist must reach the collector promptly. If a member sends the letter to your credit union (as the original creditor) and your CU does not route it to the collector within a day or two, you have created a gap where the collector continues contact in good faith but the member’s legal right has already been invoked.
- The account must be flagged across all contact channels. A cease-and-desist stops telephone calls, letters, emails, and texts. A collector who stops calls but continues email is still in violation.
Credit unions should audit whether their loan-servicing system and their third-party collector systems share a cease-and-desist flag in real time. This is one of the most common exam findings in vendor-management reviews at the state level.
How a role-aware workflow platform helps
Software cannot decide legal status by naming itself. It can make the operating model legible and enforce the controls approved for each participant and account:
- Make every participant explicit. Record the creditor, owner, servicer, collector, firm, representative, communication sender, and decision-maker independently instead of collapsing them into one label.
- Bind policy to the real context. Select disclosures, quiet hours, frequency rules, representation blocks, channel permissions, and approval gates from the participant, state, account, and communication context.
- Preserve evidence and fail closed. Keep the contact-data provenance, authority, policy version, decision, and delivery result. If classification or required configuration is missing, hold the action for review.
The practical result is one shared record of the account and its actors, with different controls and views for each role. Counsel still determines legal coverage; the platform makes that determination enforceable and auditable.
Role-aware workflow controls
What ‘pilot’ looks like in practice
Most credit unions want to validate the workflow before authorizing a paid subscription. The pilot structure is explicit:
- No-charge pilot. The credit union enrolls an approved account segment and tests configured workflows. The pilot does not auto-convert and creates no platform invoice.
- Flat monthly subscription only after separate authorization. Standard service begins only after an owner accepts a versioned order form and pricing schedule. Charges never vary with amounts collected, settlements, or recovery outcomes.
- Participant policy confirmed at onboarding. Before live communication, the platform records the data agreement, legal terms, participant roles, sender authority, jurisdictional policy, and compliance approval for the workflow.
- Audit trail by default. Every offer, every communication, every payment, every member response produces an immutable log that your CU can pull for examiner review without asking the vendor for a data export.
- Member contact policy is versioned. Approved cadence, channel, representation, cease-communication, and disclosure rules are encoded in software and bound to the participant/account context.
What examiners are looking for in 2026
NCUA and state regulators have been clear that Reg F compliance is a vendor management priority, not just a direct-collections priority. In 2025 and 2026, examination findings increasingly target the gap between what creditors believe their third-party collectors are doing and what the collectors are actually doing.
The three areas generating the most findings:
- Cease-and-desist routing gaps. Cease-and-desist letters arriving at the credit union and not reaching the collector within 48 hours, leaving the collector contacting a member whose rights have already been invoked.
- Electronic opt-out confirmation failures. Collectors not providing written confirmation of opt-out to the consumer within the required window, and not updating the account flag across all contact channels.
- Insufficient vendor oversight documentation. Credit unions that cannot produce evidence of regular vendor audits, contract reviews, or complaint-tracking for their collection vendors.
The platform does not replace legal analysis or participant oversight. It turns the approved operating model into shared, testable controls.
See how Debt Digest works for credit unions
No-charge pilot with no automatic conversion. Standard service requires a separate subscription order form. No contingency or recovery-based pricing.
See the credit union overview