Private Money Lender
Compliance Guide 2026
By Anthony Geraci, Managing Partner & CEO, Geraci LLP | June 2025
Compliance is the single biggest operational risk facing private money lenders today. The regulatory landscape has grown increasingly complex, with overlapping federal and state requirements that can trip up even experienced hard money lenders and private money lenders. A compliance violation doesn't just mean a fine — it can mean a borrower walks away from a loan they rightfully owe, and a court won't let you do anything about it.
This guide covers the key compliance areas every private lender needs to understand in 2026, with practical guidance on how to stay on the right side of the law.
Key Takeaways
Business-purpose loans made by private money lenders are generally exempt from TILA (Truth in Lending Act), Dodd-Frank's Ability to Repay rule, RESPA, and most consumer lending regulations. However, this exemption only applies when the loan is genuinely for a business purpose, and the business-purpose classification must be properly documented.
State-level compliance is where most private money lenders encounter problems. Licensing requirements, usury limits, disclosure obligations, and foreclosure procedures vary significantly from state to state. States like Oregon, Washington, and Nevada require lending licenses even for business-purpose loans.
Compliance violations can void a lender's ability to enforce a loan. Courts have ruled that borrowers can walk away from loans when lenders fail to meet state disclosure or licensing requirements — regardless of whether the borrower actually repaid the money.
Related: Complete Guide to Loan Documents | Deed of Trust vs. Mortgage Guide | How to Lend in Multiple States
Federal Regulations
The Business-Purpose Exemption: Your Most Important Shield
The single most important compliance concept for private lenders is the business-purpose exemption. Most federal consumer lending regulations — including the Truth in Lending Act (TILA), the Real Estate Settlement Procedures Act (RESPA), and the Dodd-Frank Act's Ability-to-Repay rules — apply to consumer-purpose loans, not business-purpose loans.
If your loan is made primarily for a business purpose — such as acquiring, renovating, or investing in real property — these consumer regulations generally don't apply. This is why the vast majority of private lending activity focuses on business-purpose loans: fix-and-flip, bridge, construction, and investment property loans where the borrower is using the property for business, not personal residence.
But here's the critical part: you need to document the business purpose properly. A loan that's actually a consumer loan but dressed up as a business-purpose loan will get unwound by a court. The business-purpose determination should be supported by the borrower's stated use, the nature of the property, the borrower's business plan, and the overall circumstances of the transaction.
When TILA Does Apply
If your loan is a consumer-purpose loan — for example, if the borrower intends to occupy the property as their primary residence — TILA and Regulation Z kick in. This means you need to provide specific disclosures including the Annual Percentage Rate (APR), finance charges, total amount financed, and total of payments. The timing of these disclosures is also regulated.
Non-compliance with TILA can result in statutory damages, enhanced damages, and the borrower's ability to rescind the loan for up to three years. For private lenders, this is a potentially catastrophic exposure — which is why getting the business-purpose determination right at the front end is so critical.
Dodd-Frank and Ability-to-Repay
The Dodd-Frank Act's Ability-to-Repay (ATR) rule requires lenders to make a reasonable, good-faith determination that a borrower can repay a residential mortgage loan. This rule applies to consumer-purpose residential mortgages — not to business-purpose loans.
However, if a private lender makes a consumer-purpose loan without complying with ATR, the borrower can assert it as a defense to foreclosure, potentially for the entire life of the loan. This is another reason the business-purpose exemption is so important to maintain.
State-Level Compliance
Licensing Requirements
Whether you need a license to make loans varies significantly by state. Some states, like Oregon, Washington, and Nevada, require licensing even for business-purpose loans. California has a complex framework where loans brokered by a DRE-licensed broker may not need a separate lending license. Other states have broad exemptions for business-purpose lending.
Operating without a required license is one of the most serious compliance violations a lender can commit. In some states, unlicensed lending can render the loan void and unenforceable — meaning you lose your entire investment, not just a penalty amount. Before entering any new state, a licensing analysis should be the first step.
Usury Laws
Every state has some form of usury limit — the maximum interest rate that can be charged on a loan. These limits vary dramatically: some states have generous limits or broad exemptions for business-purpose loans, while others have strict caps that can catch private lenders off guard.
Usury violations are among the most punished in lending law. Depending on the state, penalties can include forfeiture of all interest, treble damages, criminal penalties, and even voiding of the loan entirely. Some states apply usury limits to total charges (including fees and points), not just the stated interest rate — which means a loan with a seemingly compliant rate can still be usurious when origination fees are factored in.
State-Specific Disclosure Requirements
Beyond federal requirements, many states impose their own disclosure obligations on lenders. California's MLDS, New York's banking department disclosures, and various other state-specific forms must be provided at the right time in the right format. Failure to provide required disclosures can give borrowers rescission rights or damage claims.
Practical Compliance Steps
Based on two decades of helping private lenders navigate compliance, here are the practical steps every lending operation should take:
1. Document the business purpose on every loan. Don't rely on verbal representations. Get it in writing, supported by the borrower's business plan, the property type, and the intended use. Build this into your intake process.
2. Know the licensing requirements in every state where you lend. This means actually getting a legal analysis — not relying on what another lender told you at a conference. Licensing requirements change, and what was true two years ago may not be true today.
3. Run a usury analysis before you set your rates. Include all fees, points, and charges — not just the interest rate. Some states include certain closing costs in the usury calculation that you might not expect.
4. Use state-specific documents for every loan. Generic templates are compliance landmines. Your promissory note, security instrument, disclosures, and riders should all be tailored to the specific state where the property is located.
5. Stay current. Regulations change. States amend their statutes, courts issue new decisions, and federal agencies update their guidance. A compliance framework that was solid two years ago may have gaps today.
How Automate Loan Docs Keeps You Compliant
Automate Loan Docs was built with compliance at its core. The platform's compliance engine automatically applies state-specific requirements to every document package: the correct security instrument, required disclosures, applicable riders, and jurisdiction-specific provisions. When regulations change, the templates are updated by the attorneys at Geraci LLP — the same firm that's been advising private lenders on compliance with over 30 years of combined experience.
This doesn't replace the need for legal counsel on complex transactions or licensing questions. But it eliminates the most common compliance failures: using wrong documents for the state, missing required disclosures, and generating internally inconsistent loan packages.
Compliance Shouldn't Keep You Up at Night
See how Automate Loan Docs generates fully compliant document packages — with state-specific disclosures, riders, and security instruments built in.
Book a Demo