Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

OCC and FDIC Drop Reputation Risk from Bank Supervision: What Your Compliance Program Must Do Now

The June 9, 2026 OCC/FDIC final rule prohibits regulators from citing reputation risk in examinations. Here's what changed, what the rule does and doesn't require, and the specific compliance program updates every bank and fintech needs to make.

By Rebecca Leung · June 10, 2026 ·
Table of Contents

If an examiner ever told your bank to reconsider serving a firearms dealer, a cryptocurrency exchange, or a payday lender because of “reputational concerns” — that directive is now illegal.

The OCC and FDIC’s June 9, 2026 final rule doesn’t just shift terminology. It changes who has legal authority over your customer relationships. And the follow-up action on June 2, when the Fed, OCC, and FDIC jointly scrubbed “reputation risk” references from 15 interagency guidance documents, signals that this is a structural shift, not a pendulum that swings back in the next administration.

Here’s what compliance teams actually need to do about it.

TL;DR

  • OCC and FDIC final rule (effective June 9, 2026) prohibits regulators from taking adverse action — including CAMELS rating downgrades, MRAs, and enforcement actions — based on “reputation risk” unconnected to measurable financial or operational condition
  • Adverse action now includes any requirement, instruction, or encouragement to close accounts or restrict services based on a customer’s political views, constitutionally protected speech, or lawful-but-disfavored business activities
  • On June 2, Fed, OCC, and FDIC jointly removed “reputation risk” language from 15 interagency guidance documents covering asset securitization, BOLI, subprime lending, CIP FAQs, and cybersecurity guidance
  • The rule constrains regulators, not banks — banks can still assess franchise and reputational risk as a business judgment; they just can’t cite regulatory pressure as the basis
  • Compliance programs need to review account closure policies, customer selection criteria, and risk appetite language that references regulatory reputation risk as a decision driver

What “Reputation Risk” Actually Was in Supervision

The phrase appears throughout pre-2026 examination guidance in ways that conflated two distinct concepts.

The first is franchise risk: how a particular customer, product, or business line affects your institution’s standing with depositors, investors, counterparties, and your community. That’s a legitimate, measurable business concern. A bank that serves a customer base with high fraud exposure faces real operational and reputational consequences regardless of what any regulator says.

The second is regulatory reputation risk: the category of supervisory criticism applied when examiners concluded that serving a particular legal industry — firearms retailers, payday lenders, cryptocurrency exchanges, cannabis-adjacent businesses — created “reputational risk” to the institution. This is the category that no longer exists as a valid exam finding.

The agencies put it plainly in the final rule: they found “no clear evidence that supervisory interference in banks’ activities or relationships in the interest of protecting the banks’ reputations has protected banks from losses or improved banks’ performance.” OCC data confirmed that reputation risk ratings in exam reports showed no predictive value for bank failures after controlling for CAMELS composite ratings. The category was, in effect, a supervisory veto on customer relationships, not a safety-and-soundness measure.

What the Final Rule Actually Prohibits

The rule defines prohibited “adverse action” broadly. Examiners can no longer:

  • Include negative language about reputation risk in exam reports, ROEs, or supervisory letters
  • Issue Matters Requiring Attention (MRAs) citing reputation risk as the primary or contributing basis
  • Downgrade CAMELS composite ratings, component ratings (including Management, Sensitivity, and Compliance), or IT ratings on reputation grounds
  • Issue enforcement actions — consent orders, cease-and-desist orders, MOUs — based on reputation risk
  • Attach conditions to merger approvals, charter applications, or branch applications on reputation grounds
  • Require capital above minimums because of reputation concerns
  • “Require, instruct, or encourage” a bank to close accounts, deny services, or exit relationships on the basis of a person’s political, social, cultural, or religious views or beliefs, constitutionally protected speech, or solely because their lawful business activities are politically disfavored

That last category is the one with the broadest operational impact. It directly addresses the debanking patterns documented over the prior decade — where banks received informal regulatory pressure to exit firearms dealers, cryptocurrency businesses, payday lenders, and politically disfavored-but-legal industries.

The 15 Interagency Guidance Documents Updated

On June 2, 2026, the three federal banking agencies jointly removed “reputation risk” language from 15 interagency guidance documents. The practical effect: every guidance document that previously told banks to consider “reputational implications” of a particular activity no longer does so.

The documents updated include guidance on:

DocumentPrevious Reputation Risk Angle
Asset securitizationReputation risk from third-party originator relationships
Subprime lendingReputational risk of association with subprime portfolios
Bank-owned life insurance (BOLI)Reputation risk of executive compensation structures
Customer identification program (CIP) FAQsReputation risk of certain CIP gaps
Home equity credit riskReputation risk from risky borrower segments
Remote deposit captureReputation risk of RDC-related fraud exposure
Counterparty credit risk managementReputation risk from counterparty quality
Cyber incident response statementsReputation risk as a response driver
Operational resilience statementsReputation risk in resilience planning
Elder financial exploitationReputation risk of exploitation-adjacent relationships
100% loan participation salesReputation risk from participation structures

For compliance teams, this means guidance citations that previously supported reputation-risk-driven decisions are no longer available. Internal policies that cite this guidance need to either cite a different rationale or be removed.

What the Rule Does Not Change

This point deserves emphasis because the framing in industry coverage has sometimes been imprecise.

The rule constrains regulators. It does not require banks to serve anyone.

Banks can still:

  • Decline to open accounts for legal businesses if they have an independent business reason (operational complexity, AML cost, strategic fit, concentration limits)
  • Exit customer relationships for safety-and-soundness reasons genuinely connected to financial or operational condition
  • Price products differently based on risk profiles that map to measurable financial metrics
  • Maintain concentration limits, credit risk policies, and AML program standards that effectively exclude some legal customer categories
  • Assess franchise risk as a business judgment — just not as a regulatory compliance output

The distinction matters because it determines how you document future decisions. A bank that exits a cryptocurrency customer because the AML monitoring cost is disproportionate to the revenue has a legitimate operational rationale. A bank that exits the same customer because an examiner flagged a “reputational concern” about cryptocurrency — that’s now the prohibited pattern.

The Debanking Context

The final rule was explicitly shaped by the documented history of regulatory pressure on financial institutions to exit industries the previous regulatory leadership viewed unfavorably: fossil fuel companies, firearms manufacturers and retailers, for-profit prisons, payday lenders, and cryptocurrency businesses.

Operation Choke Point — the 2013-2014 DOJ initiative that pressured banks to exit legal payday and firearms businesses by raising informal compliance concerns — established the playbook. The pattern continued through 2022-2024 in a different form, with FDIC correspondence documents disclosed in 2024 showing examiners asked banks to pause or restrict cryptocurrency-related activities without formal rulemaking.

The June 9 rule codifies that this practice is no longer permitted. For banks and fintechs that have been cautious about serving legal-but-disfavored industries, the regulatory backstop for those restrictions is gone.

What Your Compliance Program Must Do Now

1. Audit account closure and denial policies

Review every account closure, exit, and denial policy that cites “reputation risk” or references regulatory guidance on reputation risk as a decision driver. Policies that say “we don’t serve X because regulators view X as reputationally risky” need to be rewritten — either with a legitimate business rationale or removed.

If the business rationale for the restriction is real (AML complexity, fraud exposure, capital impact), document it on those grounds. If the only rationale was regulatory pressure, the policy needs to go.

2. Update your risk appetite statement

Risk appetite statements often include a reputation risk dimension that blends regulatory compliance obligations with business risk tolerance. That distinction matters now. Update the language to clearly distinguish:

  • Franchise risk appetite: the institution’s own judgment about how customer relationships affect its standing and sustainability (legitimate, keep it)
  • Regulatory reputation risk compliance: the supervisory obligation to avoid activities regulators flagged as reputationally risky (no longer applicable)

If your risk appetite cites OCC, FDIC, or interagency reputation risk guidance as the source of obligations in this category, those citations are stale. Revise to reference actual regulatory obligations — and note that reputation risk is no longer an exam category.

3. Brief your board and senior management

Directors and senior management who’ve been approving customer exit decisions or product restrictions because examiners signaled “reputational concerns” need to understand the new landscape. The examiner no longer has legal authority to downgrade your rating or issue an MRA on reputation grounds.

More importantly: if future decisions to exit customer relationships are made, they need to be your institution’s independent business judgment — documented as such in board minutes, credit committee minutes, and risk committee records.

4. Review pending and recent MRA remediation

If your institution currently has open MRAs or informal supervisory expectations with reputation risk as a stated or contributing basis, those findings are worth revisiting with your examiner relationship manager. The MRA remediation playbook covers how to approach regulator discussions about modifying or closing findings — a useful framework if you’re managing legacy reputation-risk-driven supervisory items.

5. Retain your internal franchise risk framework

The reputational risk KRI post published earlier this week — “Reputational Risk KRIs: What to Measure Now That Examiners No Longer Will” — addresses this directly: examiners stopped watching, the risk didn’t leave.

Customer complaints, social media signal, media coverage, compliance leadership attrition, and bank partner RFI volume are all meaningful franchise risk indicators that your institution should still be tracking. The difference is that these are now business risk management tools, not regulatory compliance outputs. Keep measuring them; just stop treating examiner silence as a substitute.

6. If you’ve been cautious about legal-but-disfavored industries — reassess

This is the practical question for a lot of community banks and fintechs: should we revisit our posture toward cryptocurrency clients, firearms retailers, cannabis-adjacent businesses, or payday lenders?

The answer is: that’s now genuinely a business decision. Assess the AML risk, the operational complexity, the credit profile, the concentration impact, and the franchise risk on your own judgment. The regulatory backstop that previously provided cover for declining these relationships is gone. So is the regulatory pressure that made those declinations feel safer.

Remaining Regulatory Dimensions

One important caveat: the OCC and FDIC rule binds those two agencies. The Federal Reserve participated in the June 2 guidance updates but did not issue a parallel final rule. State member banks supervised by the Fed are covered by the guidance changes, but the binding codification in federal regulation applies specifically to national banks and federal savings associations (OCC) and state nonmember banks and state savings associations (FDIC).

CFPB, NCUA, and FinCEN are separate authorities. Their existing guidance may still reference reputational considerations in specific contexts — check current guidance before concluding a particular customer relationship is now free of all supervisory reputation risk considerations.

AML/BSA requirements remain fully intact. A customer posing genuine money laundering risk can still be declined or exited on BSA/AML grounds. What’s changed is the standalone “reputation risk” overlay that treated legal industry membership as an independent risk factor.

The FFIEC IT Examination Handbook walkthrough is worth reviewing in this context — it’s a useful reference for understanding what exam findings under the new framework will and won’t look like.

So What?

The rule is real, it’s in effect, and it changes the supervisory relationship in a meaningful way. For compliance programs, the work is mostly internal housekeeping:

  • Audit account closure and customer selection policies for reputation risk citations
  • Update risk appetite language to distinguish franchise risk from regulatory reputation compliance
  • Brief your board on the new examiner authority boundaries
  • If you have open MRAs with a reputation risk basis, consider approaching examiners about closure or modification
  • Retain your internal franchise risk framework — but now manage it as a business risk tool, not a regulatory obligation

For banks and fintechs that have been cautious about legal-but-politically-disfavored industries: the regulatory cover for those restrictions is gone. That cuts both ways — examiners can’t push you out of those relationships, but they can’t prop up your risk appetite decisions with supervisory authority either. Whatever you decide going forward, own it as your own business judgment.


External sources: OCC Bulletin 2026-12 · Federal Register Final Rule · FDIC Press Release · OCC Interagency Guidance Update · Goodwin Analysis — June 2026 Guidance Removal

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does this rule mean banks MUST serve firearms dealers, crypto exchanges, or cannabis businesses?
No. The rule constrains regulators, not banks. Banks can still decline to serve any legal business for their own independent business reasons — concentration risk, AML complexity, operational fit. What they cannot do is use regulatory reputation risk pressure as the justification. The decision just has to be theirs, documented as a business choice.
What's the difference between 'reputation risk' under the rule and 'franchise risk' that banks can still assess?
Reputation risk under the rule means supervisory concerns about public perception not connected to measurable financial or operational condition. Franchise risk is a legitimate business concept: how a customer relationship affects your institution's standing with other customers, counterparties, or investors. Banks can continue to assess and price franchise risk internally. The rule only bars regulators from weaponizing 'reputation' to push banks toward or away from legal customer categories.
Can examiners still flag concerns about a bank's business model under the new rule?
Yes — but only on financial or operational grounds. Examiners can still cite credit concentration risk, AML program deficiencies, capital adequacy concerns, or operational complexity associated with a customer segment. What they cannot do is criticize or rate-downgrade a bank because its customer base is perceived as 'reputationally risky' in a way unconnected to those measurable dimensions.
What happens to banks that closed accounts or restricted services under regulatory reputation risk pressure before June 9?
The rule is prospective. There's no retroactive cure requirement. However, if a bank has ongoing policies that explicitly cite regulatory reputation risk guidance as the basis for account closures or denials, those policies should be reviewed and updated — both to remove the regulatory citation and to document any continued restrictions on their own business rationale.
Does the Federal Reserve's removal of reputation risk from interagency guidance have the same legal force as the OCC/FDIC final rule?
Not exactly. The OCC and FDIC issued a binding final rule codified in federal regulation. The Federal Reserve joined OCC and FDIC in updating 15 interagency guidance documents (on June 2, 2026) to remove reputation risk references, but the Fed did not issue its own parallel final rule. State member banks supervised by the Fed are covered by the interagency guidance changes but not the binding OCC/FDIC regulation directly.
Should banks now delete or dismantle their internal reputational risk frameworks?
No. Internal franchise and reputational risk management remains a legitimate — and important — business function. What's gone is the regulatory mandate to manage reputation risk as an exam-driven supervisory category. Your board and management can still assess how a particular business relationship affects your institution's standing. Just document those decisions as business judgments, not as compliance with regulatory direction.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.