Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

The OCC and FDIC Reputation Risk Rule Is Now Effective: What Compliance Programs Must Change After June 9, 2026

The OCC and FDIC formally removed 'reputation risk' from their supervisory frameworks on June 9, 2026. Here's what the final rule actually prohibits, what it doesn't change, and what compliance teams need to update now.

By Rebecca Leung · June 23, 2026 ·
Table of Contents

TL;DR

  • As of June 9, 2026, the OCC and FDIC are prohibited from criticizing or taking adverse action against a bank on the basis of “reputation risk” — it’s no longer a standalone supervisory risk category
  • Regulators can no longer require institutions to close, refuse, or terminate accounts based on political, social, cultural, or religious views, or lawful business activities perceived to present reputational concerns
  • The rule does NOT eliminate AML/KYC, credit, operational, or safety-and-soundness review — those rationales remain fully valid and legally distinct
  • The Federal Reserve did not join this rule; state member banks still face a different supervisory analysis

If your compliance program still treats “reputational risk” as a standalone risk category that examiners will ding you on, you’re working off guidance that formally expired June 9, 2026. The OCC and FDIC just removed it from their supervisory toolbox entirely.

This isn’t a deregulatory gesture or a softening of enforcement posture. It’s a structural change to what regulators are legally permitted to cite when criticizing your institution. Understanding that distinction — what changed, what didn’t, and what that means for compliance teams — is what separates institutions that handle the transition cleanly from the ones that get it wrong in both directions.

What the OCC and FDIC Actually Did

On April 7, 2026, the OCC and FDIC jointly issued a final rule codifying the prohibition on the use of reputation risk in their supervisory programs. The rule was published in the Federal Register on April 10, 2026 (Document 2026-06947) and became effective June 9, 2026. It’s covered by OCC Bulletin 2026-12.

The rule does three specific things:

1. Eliminates reputation risk as a standalone supervisory category. The agencies concluded that reputation risk “has not proven useful in predicting bank failures or enhancing safety and soundness, and instead has injected a high degree of subjectivity into examinations.” That’s a direct indictment of how the category was being used — and it’s accurate. A risk category that depends on public perception rather than measurable financial or operational metrics is a category that creates unpredictability for both examiners and institutions.

2. Prohibits adverse action based on reputational concerns. The rule bars the OCC and FDIC from criticizing, formally or informally, or taking adverse action against a supervised institution or any employee on the basis of reputation risk. That language matters: this applies to informal exam feedback — the MRA-adjacent comments, the verbal criticism, the “we’re concerned about how this looks” messaging that doesn’t always show up in formal findings but shapes institution behavior.

3. Prohibits coerced account closures and relationship exits. This is the provision with the broadest practical reach. The rule explicitly prohibits the agencies from requiring, instructing, or encouraging an institution to close customer accounts, refrain from providing accounts or products, or terminate relationships on the basis of:

  • A person’s or entity’s political, social, cultural, or religious views or beliefs
  • Constitutionally protected speech
  • Lawful business activities that are perceived to present reputation risk

The final rule also updated the definition of “reputation risk” itself to expressly reference an institution’s “operational condition” alongside its financial condition — a definitional fix designed to close a potential loophole where examiners might have argued operational concerns were technically a subset of reputational ones.

What This Doesn’t Change

This is the part most compliance teams need to read carefully, because the rule is already generating interpretive overreach in both directions — from institutions that think they now need to bank every legal business that asks, to institutions that think the rule is cosmetic and changes nothing.

AML/KYC obligations are unchanged. If you’re declining a crypto exchange because you can’t satisfy the transaction monitoring and beneficial ownership requirements under your BSA/AML program, that’s not reputation risk. That’s BSA/AML risk. FinCEN’s Customer Due Diligence rule, the Bank Secrecy Act’s know-your-customer expectations, and the SAR filing obligations all remain. The rule doesn’t create a defense for weak AML programs.

Safety and soundness criteria remain. Credit risk, liquidity risk, operational risk, and other examination categories exist independently of reputation risk. An examiner who has concerns about your operational condition, capital adequacy, or management quality can still raise them — they just can’t dress up those concerns as reputation risk.

Account decision-making authority remains. Banks can still decline accounts. The rule doesn’t create an obligation to serve any particular customer or industry. It prohibits the agencies from using reputation risk as the basis for pressuring those decisions. Your internal policies can still factor in concentration risk, AML complexity, or operational capacity — as long as those are the documented rationales.

Formal enforcement is unaffected. Consent orders, civil money penalties, and formal supervisory agreements issued for specific legal violations aren’t touched by this rule. An institution that violated the BSA, engaged in UDAAP, or operated with unsafe and unsound practices faces the same enforcement exposure as before.

Why This Rule Exists: The Operation Choke Point History

The context behind this rule matters if you want to understand both its scope and its limits.

Operation Choke Point was a 2013–2014 Department of Justice and FDIC initiative that used regulatory pressure to push banks away from relationships with legally operating businesses in politically disfavored industries: payday lenders, firearms dealers, short-term lenders, tobacco retailers. Banks weren’t told directly to exit these relationships — they were pressured through exam criticism framing these industries as “reputation risk” and by implication suggesting that banking them created supervisory exposure.

The approach was effective at its stated purpose and controversial for exactly that reason. Banks exited relationships with legal businesses not because of any specific legal violation, but because the cost of examiner friction wasn’t worth the revenue. Critics on both sides of the political spectrum — and eventually both the DOJ IG and the FDIC IG — found the initiative had strayed into using regulatory tools to implement de facto policy without legal authority.

The 2026 rule is the formal resolution of that controversy at the agency level. It doesn’t reverse any specific Operation Choke Point outcome. But it eliminates the supervisory mechanism that made the initiative possible.

For compliance teams, the practical implication is this: if your institution has policies or practices that exist primarily to avoid examiner criticism framed as reputation risk — rather than to address specific financial, operational, or AML concerns — those policies warrant review.

Industry-Specific Implications

Crypto and digital assets. Banks that avoided crypto clients specifically due to examiner skepticism about “reputational exposure” from crypto associations now face a changed landscape. Regulators cannot cite reputation risk when examining your crypto banking activities. They can, and will, assess BSA/AML program adequacy, transaction monitoring calibration, and the operational complexity of your crypto client base — but the vague “crypto looks risky” critique is no longer a permissible supervisory tool.

Cannabis. State-legal cannabis businesses remain in federal legal limbo under the Controlled Substances Act, which creates genuine AML compliance complexity regardless of this rule. The reputation risk rule doesn’t resolve the FinCEN guidance tension or the federal law conflict. What it removes is the overlay of additional examiner criticism framed as reputation risk on top of the legitimate AML complexity. The AML challenge is real; the reputation risk overlay was the subjective add-on that this rule eliminates.

Firearms dealers, politically disfavored industries. The explicit protection of “constitutionally protected speech” and “lawful business activities” in the rule text signals its scope. Institutions that were pressured to exit firearms, ammunition, or other politically sensitive industries under Operation Choke Point mechanics no longer face that supervisory tool.

The Federal Reserve Caveat

A significant compliance detail: the Federal Reserve did not join this rulemaking.

The final rule covers OCC-supervised national banks and federal savings associations, and FDIC-supervised state non-member banks. It does not apply to state member banks, bank holding companies, or savings and loan holding companies — all of which fall under Fed supervision.

This creates an uneven playing field that compliance teams at multi-charter banking organizations need to navigate. Your national bank subsidiary operates under the new prohibition on reputation risk examination. Your state member bank subsidiary may still face reputation risk examination from Fed examiners using the prior framework.

Watch for whether the Fed issues a parallel rule. As of this writing, it has not.

What Compliance Programs Need to Update

Risk taxonomy. If reputation risk appears as a standalone risk category in your enterprise risk management framework, operational risk policy, or annual risk assessment, update it. The category no longer has supervisory backing at the OCC or FDIC. You may still choose to track reputational concerns internally — but frame them as financial risk, operational risk, or compliance risk, and document the specific financial or operational mechanism that makes them a concern.

Customer risk assessment policies. Review the basis on which your CIP/CDD program and onboarding policies allow account declinations or terminations. Ensure the documented rationale for any declination is specific and financial — not a reputational catchall. “We cannot adequately satisfy the BSA/AML monitoring requirements for this customer profile” is a defensible basis. “This customer presents reputation risk” is not, if that’s the extent of the documentation.

Issues management. If you have open issues or MRAs that reference reputation risk as a primary finding basis from prior examinations, those findings should be closed or reclassified once remediation is complete. Use a structured issues management process — the kind that tracks finding basis, remediation steps, and closure evidence — to work through the cleanup. A dedicated issues tracking system helps you maintain the audit trail as you close out legacy reputation risk findings and document the policy updates that replace them.

Staff training. Your front-line relationship managers and compliance staff have learned, over years, to flag “reputational risk” as a reason to escalate or decline accounts. That instinct needs to be retrained toward specific, articulable financial and compliance risk criteria.

The Ongoing Challenge: How to Say No Without Saying Reputation Risk

Here’s the practical tension that doesn’t disappear with this rule: institutions will still sometimes need to decline accounts or exit relationships with legally operating businesses. The rule doesn’t eliminate that discretion. What it changes is how you document and defend the decision.

If your true concern about a customer is AML complexity, say that — and document the specific BSA/AML gap. If your concern is operational capacity (you can’t handle the compliance workload for this account profile), say that. If your concern is credit quality or financial risk, document the specific financial metrics.

What you can no longer do, at least at OCC- and FDIC-supervised institutions, is use “reputation risk” as a freestanding reason. The label is gone. The underlying analysis — financial, operational, compliance-based — remains exactly as important as it always was.

So What?

The deregulation wave of 2026 has produced several structural supervisory changes: reduced exam frequency for well-rated community banks, advisory-only model risk guidance, a CFPB enforcement shift toward collaboration. This rule is different in kind — it’s a legal prohibition, not a softening of tone. Examiners at OCC and FDIC-supervised institutions are now prohibited from a specific category of supervisory criticism, regardless of who runs those agencies.

For most compliance teams, the practical work is documentation hygiene: update your risk taxonomy, tighten your account decision rationale documentation, close legacy reputation risk findings with properly documented evidence. The underlying risk analysis you’ve been doing — AML, operational, financial — doesn’t change. Only the label you’re no longer allowed to use.

If your institution has practices built around avoiding reputation risk criticism that have no financial or operational substance behind them, this is the moment to figure out which practices reflect real risk management and which reflect examiner-driven compliance theater.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does the OCC/FDIC reputation risk rule mean banks must now accept crypto, cannabis, or firearms customers?
No. Banks still have discretion to decline customers for financial, credit, operational, or AML/fraud risk reasons. What's prohibited is using vague 'reputation risk' as the examiner-cited rationale. If you decline a cannabis dispensary, your documented basis should be specific — unresolvable AML risk, cash-handling limitations, FinCEN guidance compliance — not just 'this looks bad for us.'
The Federal Reserve wasn't part of this rule. What does that mean for state member banks?
Correct. The final rule covers only OCC-supervised national banks and FDIC-supervised state non-member banks. State member banks (supervised by the Fed) and bank holding companies aren't covered by this specific rule. The Fed has not issued a parallel rule, so its supervisory approach on reputation risk remains unchanged.
What's Operation Choke Point and why does this rule matter in that context?
Operation Choke Point was a 2013–2014 DOJ/FDIC initiative that pressured banks to exit relationships with legally operating but politically disfavored businesses (payday lenders, firearms dealers, short-term lenders) by flagging them as 'reputation risk.' Critics argued the approach was used to de facto debank legal industries without due process. This 2026 rule formally prohibits that supervisory mechanism.
Can examiners still downgrade S (sensitivity) or management CAMELS ratings for reputation-related concerns?
Examiner criticism must now be grounded in financial condition, operational condition, or safety and soundness — not subjective public perception concerns. Examiners who want to raise reputational concerns will need to translate them into a specific financial or operational risk to retain supervisory footing. That's a higher evidentiary bar than 'this looks risky.'
What should we actually update in our compliance program?
Review your risk taxonomy and remove 'reputation risk' as a standalone examination risk category. Update customer risk assessment policies so account decisions reference specific financial, AML, or operational risk rationale rather than reputational language. Retrain staff on the distinction. Document that the basis for any account termination or refusal meets a financial-basis standard, not a public-perception one.
Does this rule affect formal enforcement proceedings?
No. The rule applies to bank supervision and examination programs, not to formal enforcement proceedings, corrective action orders, or bank failure resolution. An institution facing safety-and-soundness problems can still be subject to the full enforcement toolkit — the rule narrows what reputation risk language can justify in those proceedings, not whether enforcement can occur.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.