Reputational Risk Is Gone From Federal Supervision — Now Banks Have to Audit Everything They Built Around It
Federal supervisors eliminated reputation risk, but it's still wired into your BSA/AML, account-exit, and vendor policies. Learn what to audit and revise.
By Lex
Two things landed in the same week, and most of the trade press filed them under the same headline. On June 2, the Federal Reserve, FDIC, and OCC jointly reissued 15 interagency supervisory documents — spanning 27 years of guidance, from a 1997 statement on loan participations through the 2024 statement on elder financial exploitation — with every reference to reputation risk stripped out — the latest step in a methodical dismantling of the rubric critics labeled "Operation Choke Point 2.0." One week later, on June 9, the OCC/FDIC final rule codifying the elimination of reputation risk from supervision took effect. That rule prohibits the agencies from criticizing or taking adverse action against an institution on the basis of reputation risk, defined as any risk that could "negatively impact public perception of the institution for reasons not clearly and directly related to the financial or operational condition of the institution."
The coverage has been almost entirely about the politics — debanking, the executive order, who won. That is the wrong story for anyone who runs a compliance program. The operational story: removing reputation risk from the supervisor's vocabulary does not remove it from yours. The concept has been wired into bank policy for two decades — into BSA/AML alert escalation, account-exit criteria, credit underwriting overlays, restricted-industry lists, vendor risk ratings, and cyber-incident escalation. The standards those policies were built to satisfy are gone. The policies are not. A bank that keeps running reputation-risk machinery without revising it now carries an exposure pointed in the opposite direction from the one most compliance officers are watching.
How we got here
The arc is short and deliberate. In August 2025, President Trump issued Executive Order 14331, "Guaranteeing Fair Banking for All Americans," directing agencies to remove statements encouraging the consideration of reputation risk from guidance and supervisory policies. The agencies were already moving. On March 20, 2025, the OCC removed reputation risk from its Comptroller's Handbook booklets and instructed examiners to stop examining for it; on June 23, 2025, the Board announced reputation risk would no longer be a component of its bank examinations.
Then came the codification. On April 7, 2026, the FDIC and OCC jointly issued a final rule codifying the elimination of reputation risk from their supervisory programs, effective June 9, 2026, and codified at 12 CFR § 4.91 (OCC) and 12 CFR § 302.100 (FDIC). The Federal Reserve has not finished the job. On February 23, 2026, the Board issued its own proposed rule to codify the same removal; the proposal mirrors the OCC and FDIC approach but has not yet been finalized. "We have heard troubling cases of debanking—where supervisors use concerns about reputation risk to pressure financial institutions to debank customers because of their political views, religious beliefs, or involvement in disfavored but lawful businesses," Vice Chair for Supervision Michelle W. Bowman said in the February statement — language the agencies echoed in June.
What the reissued guidance touches is the tell. The 15 documents include the asset-securitization guidance, the expanded subprime-lending guidance, the Customer Identification Program FAQs, the Sound Practices to Strengthen Operational Resilience, the Interagency Statement on Elder Financial Exploitation, the counterparty-credit-risk guidance, the home-equity credit-risk guidance, and a cluster of cyber statements on ATM and card-authorization attacks and denial-of-service attacks. These are not political documents. They are the load-bearing references behind ordinary risk programs — which is precisely why "reputation risk" got embedded in those programs in the first place. (The reissuance carried the names of the three banking agencies; several underlying documents were originally issued jointly with the other FFIEC members, including the NCUA, and with FinCEN, per OCC Bulletin 2026-23.)
The rule binds the regulator, not the bank — and that is the trap
Read the final rule for what it actually does, not what the press release celebrated. It constrains only the two agencies and includes an anti-evasion framework that prohibits supervisors from using traditional risk categories such as credit, operational, or compliance risk as a pretext to supervise for reputation risk; all existing safety-and-soundness, BSA/AML, OFAC, and consumer-protection obligations on institutions remain in force. The agencies were emphatic on the point. The final rule "does not impose requirements or obligations on supervised institutions."
That sentence is reassuring and operationally misleading at once. Nothing in the rule compels a bank to touch a single policy. But the Federal Register record also concedes institutions "may incur some voluntary costs associated with making changes to their compliance policies and procedures," and brushes off a commenter's warning that banks would need substantial revisions to policies and training by repeating that the rule applies only to the agencies. The awkward part is what that leaves behind. The supervisory expectation that justified building the escalation triggers and exit criteria has been withdrawn; the internal apparatus that answered it has not. The question is no longer whether the examiner expects this — it is what the criterion now rests on, if not an expectation that no longer exists. Whether continuing to run those criteria is merely stale or affirmatively risky has a clear answer: the latter, for two reasons.
The anti-evasion inference cuts toward the bank
Start with the exam room. The rule does not just delete a risk category; it tells examiners that dressing reputation risk up as something else is itself prohibited. The anti-evasion framework bars supervisors from using credit, operational, or compliance risk as a pretext for reputation concerns. The Federal Register makes the BSA/AML application explicit: because AML supervision is broad, the agencies acknowledged the risk that BSA/AML-focused actions could indirectly address reputation risk, and barred supervisors from using those concerns as a pretext.
Now flip that lens onto a bank's own files. A BSA/AML escalation procedure that lists "reputational risk" as a SAR-decisioning or account-exit tripwire, or a restricted-industry list justified by "reputational concern," produces exactly the documentary signature the anti-evasion provision was written to catch. The examiner is barred from manufacturing a reputational result through the AML channel — but a bank whose own AML taxonomy routes decisions through a reputational label has muddied whether its program is risk-based or perception-based. In the first post-June-9 exam cycle, the cleanest BSA programs will be the ones that have scrubbed "reputational" out of escalation logic and re-anchored on enumerated typologies, sanctions nexus, and documented unusual activity.
The legal exposure flips direction
The second reason is the one compliance teams are not yet pricing. For years, a bank that exited a lawful-but-controversial customer had a ready answer if challenged: our regulator expected us to manage reputation risk. That cover is gone. The agencies have not only stopped crediting reputation risk — they have declared, in a codified rule and an executive order, that pressuring banks to debank lawful customers over protected views or disfavored-but-legal activity is the conduct the policy exists to stop. A reputation-risk-based closure now sits alone, defended by no supervisory standard, in a climate where debanking is the named enforcement target.
That matters most where exit criteria collide with anti-discrimination and fair-access law. An exit policy that triggers on "reputational" grounds and falls disproportionately on a protected class, or visibly on customers' political or religious activity, now invites ECOA/Regulation B and UDAP scrutiny with no prudential justification to point back to — and, in the growing roster of states with fair-access statutes, an affirmative duty cutting the other way. The plaintiffs' bar and state attorneys general read the same Federal Register the banks do. The advising law firms are already saying so: institutions should assess whether past account-closure or de-risking decisions were shaped by reputation-risk concerns and consider what the new landscape means for existing relationships, and should think carefully about whether and how to continue or amend legacy account-closure and risk policies that take reputation risk into account.
The Federal Reserve gap
There is a structural seam worth flagging for any multi-charter organization. The Board's proposed rule, which would codify the prohibition at 12 CFR § 262.9, was issued in February with comments due April 27, 2026, and has not been finalized. A state member bank examined by the Fed operates today under a June 2025 examination-program change but no enforceable rule, while its OCC- and FDIC-supervised peers have a codified standard as of June 9. The guidance cleanup is uniform — the Fed co-signed all 15 reissued documents — but the rule-level backstop is not. Plan the audit to the stricter standard and you are covered on both charters until the Board finalizes.
One nuance keeps banks from over-correcting: the agencies did not scrub every reference. The FACT Act identity-theft "red flags" programs still reference reputation risk, because those rules require joint rulemaking across agencies; the OCC and FDIC left them intact pending a future joint rulemaking. Do not break those cross-references in a zealous find-and-replace.
What a compliance team should do in the next 60–90 days
This is a policy-inventory exercise, not a politics exercise.
- Inventory every instance of "reputation" / "reputational risk" functioning as a defined risk category or escalation trigger — across the enterprise risk taxonomy, BSA/AML alert-escalation and SAR-decisioning, CIP/account-opening and account-closure procedures, credit underwriting overlays and restricted-industry lists, third-party/vendor risk ratings, cyber-incident escalation, and new-product approval.
- Re-anchor each one to an enumerated, articulable risk — credit, liquidity, market, operational (including cyber, information security, and illicit finance), BSA/AML, OFAC, consumer compliance, or legal exposure — or move it out of the supervisory-relevant compliance stack entirely.
- Scrub "reputational risk" as a stated basis in adverse-action and account-exit memos; require a documented, enumerated rationale. This addresses the exam pretext problem and the fair-lending/UDAP exposure in one move.
- Re-paper restricted-business lists. Separate categories driven by BSA/AML, OFAC, or legal prohibition (keep) from categories driven by controversy or perception (re-justify or retire).
- Preserve, don't gut, the FACT Act red-flags references, which still reference reputation risk pending the joint rulemaking.
- Document retained business discretion explicitly. The bank may still decline or exit a relationship for legitimate reasons; it should simply stop labeling that judgment "reputation risk" in a way that invites the pretext inference or a discrimination claim.
What to watch
Three things. First, the Board's final rule — once it lands, the tri-agency framework is aligned and the state-member-bank gap closes. Second, the first post-June-9 examination cycle, which will reveal how examiners treat residual reputation-risk language in a bank's own files under the anti-evasion provision; that is the rule's real-world meaning, and it is not yet written down. Third, state fair-access and anti-debanking statutes, which keep accumulating and impose affirmative duties the federal retreat does not.
Bottom line
The federal agencies removed reputation risk from supervision; they did not, and could not, repeal the policies banks built to satisfy it. The final rule constrains the OCC and FDIC, not the institutions they supervise, and leaves every BSA/AML, OFAC, consumer-protection, and safety-and-soundness obligation intact. The risk is no longer that an examiner dings you for failing to manage reputation risk. It is that your legacy reputation-risk criteria are now an orphaned basis for adverse action — one no regulator will defend, one the anti-evasion provision makes awkward to explain in an exam, and one a plaintiff or state AG can attack. The agencies told you that you are not required to do anything. They are right about the rule and wrong about the work.
Sources
- OCC and FDIC, "Prohibition on the Use of Reputation Risk by Regulators," final rule, 91 FR 18279 (published April 10, 2026; effective June 9, 2026): https://www.federalregister.gov/documents/2026/04/10/2026-06947/prohibition-on-the-use-of-reputation-risk-by-regulators
- Federal Reserve, FDIC, OCC joint press release, "Agencies remove additional references to reputation risk," June 2, 2026: https://www.federalreserve.gov/newsevents/pressreleases/bcreg20260602a.htm
- OCC News Release NR 2026-45, "Agencies Remove Additional References to Reputation Risk," June 2, 2026: https://www.occ.gov/news-issuances/news-releases/2026/nr-ia-2026-45.html
- OCC Bulletin 2026-23, "Bank Supervision: Removing References to Reputation Risk" (lists all 15 reissued documents), June 2, 2026: https://www.occ.gov/news-issuances/bulletins/2026/bulletin-2026-23.html
- Federal Reserve Board press release and Vice Chair Bowman statement on the proposed rule, February 23, 2026: https://www.federalreserve.gov/newsevents/pressreleases/bcreg20260223a.htm
- Troutman Pepper Locke / Consumer Financial Services Law Monitor, analysis of the June 2 interagency guidance update, June 3, 2026: https://www.consumerfinancialserviceslawmonitor.com/2026/06/federal-banking-agencies-take-next-step-in-dismantling-reputation-risk-in-supervision-by-updating-interagency-guidance/
- Winthrop & Weinstine, "OCC and FDIC Codify the Prohibition on the Use of Reputation Risk in Supervision," April 2026: https://winthrop.com/bold-perspectives/occ-and-fdic-codify-the-prohibition-on-the-use-of-reputation-risk-in-supervision/